
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16801 is a code injection vulnerability (CWE-94) in the variables feature of Devolutions PowerShell Universal that allows an authenticated user with variable write permission to execute arbitrary PowerShell code. The flaw affects Devolutions PowerShell Universal version 2026.2.2 and earlier (all versions prior to 2026.2.3.0). It was published on July 24, 2026, with a patch advisory released the same day. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Devolutions Advisory).
The root cause is improper neutralization of user-supplied input in the variables feature (CWE-94: Improper Control of Generation of Code). When an authenticated user with variable write permission creates or modifies a variable, the supplied value is written to a variables configuration file without adequate escaping or sanitization. A crafted variable value containing PowerShell code can break out of the expected data context and be interpreted as executable code when the configuration file is subsequently processed by the PowerShell Universal runtime. Exploitation requires network access and a low-privilege authenticated account with variable write permissions — no user interaction or elevated privileges beyond that are needed (GitHub Advisory, Devolutions Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary PowerShell code with the privileges of the PowerShell Universal process, resulting in high impact to confidentiality, integrity, and availability. Depending on the process privilege level, an attacker could exfiltrate sensitive data, modify system configurations, install backdoors, or disrupt service availability. The scope of impact is contained to the affected system, but lateral movement is possible if the PowerShell Universal process has access to other network resources or credentials (GitHub Advisory).
There is no public proof-of-concept exploit code known at this time, and no evidence of in-the-wild exploitation has been reported (Devolutions Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable, as it requires an authenticated session with specific variable write permissions. The EPSS score is approximately 0.29% (22nd percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
"; Start-Process calc.exe; ").powershell.exe, cmd.exe, net.exe, curl.exe, or reverse shell utilities).Devolutions has released a patch in PowerShell Universal version 2026.2.3.0, which addresses the improper escaping of variable values written to the configuration file. Organizations should upgrade to version 2026.2.3 or later as the primary remediation step (Devolutions Advisory, GitHub Advisory). As interim workarounds, restrict variable write permissions to only highly trusted users, audit existing variables for suspicious content (e.g., embedded PowerShell syntax), and monitor for unauthorized variable modifications via audit logs.
The vulnerability received brief coverage on social media, including a mention on Mastodon via The Hacker Wire account shortly after disclosure. No significant vendor statements beyond the official Devolutions advisory, nor notable independent researcher commentary or major media coverage, have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."